New OAuth App features: Multiple redirect URIs, wildcarding, and token expiration and refresh #204963
Replies: 9 comments 5 replies
This comment was marked as spam.
This comment was marked as spam.
This comment was marked as spam.
This comment was marked as spam.
This comment was marked as off-topic.
This comment was marked as off-topic.
|
@hpsin was this reverted? We no longer have the option to set wildcard matching. |
|
204963 |
This comment was marked as spam.
This comment was marked as spam.
|
These are great improvements, especially support for refresh tokens and multiple redirect URIs. Both have been long-standing pain points when managing development, staging, and production environments. The per-URI wildcard option is a nice addition, but I appreciate the emphasis on using it only when necessary. Thanks for continuing to modernize the OAuth platform. |
|
The line worth re-reading: if an app has a single redirect URI, wildcard matching has been on since the app was created. So for most existing apps this isn't an opt-in, it's an opt-out nobody knew they had. Is that state readable anywhere outside the settings UI? Clicking through app settings doesn't scale, and this is the kind of thing you want to assert in CI rather than remember to check. |
|
Re: [community/community] New OAuth App features: Multiple redirect URIs,
wildcarding, and token expiration and refresh (Discussion #204963)
β¦On Wed, 9 Sept 2026, 11:32β―pm Hirsch Singhal, ***@***.***> wrote:
Agreed. We have APIs for app registration management on our near-term
backlog but no concrete dates to share just yet. I wish we had something
better for you here - I know "terraform for apps" is high on the list of
requests and we would love to get there.
β
Reply to this email directly, view it on GitHub
<#204963?email_source=notifications&email_token=CMGY2OTQWRH2UY5Y5FXF7QL5OHK7LA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBTG43DKMZZUZZGKYLTN5XKM3LBNZ2WC3FFMV3GK3TUVRTG633UMVZF6Y3MNFRWW#discussioncomment-18376539>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/CMGY2OWNW3OLBIJKXNZTFJD5OHK7LAVCNFSNUABIKJSXA33TNF2G64TZHMZTAMJVG4ZTGNBUHNCGS43DOVZXG2LPNY5TCMBWGE3DGNJTUF3AE>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/CMGY2OTNYH5F2P2SSBF2LTD5OHK7LA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBTG43DKMZZUZZGKYLTN5XKM3LBNZ2WC3FFMV3GK3TUVJTG633UMVZF62LPOM>
and Android
<https://github.com/notifications/mobile/android/CMGY2OQAJ7BHQEPCIRF7GPD5OHK7LA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBTG43DKMZZUZZGKYLTN5XKM3LBNZ2WC3FFMV3GK3TUVZTG633UMVZF6YLOMRZG62LE>.
Download it today!
You are receiving this because you are subscribed to this thread.Message
ID: ***@***.***
com>
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
π·οΈ Discussion Type
Feature Announcement
π¬ Feature/Topic Area
Apps
Body
We've shipped multiple updates to the OAuth and GitHub App platforms to help developers build more secure applications and handle more complex scenarios. See the changelog for more details.
What's new:
offline_accessscope, OAuth apps can now get a short lived (eight hours) token and a refresh token to use when the access token expires. Learn about the new tokens and scope in the docs.App developers should review their redirect URIs - if your app had only a single redirect URI registered, then it is and has been enabled for wildcard access since creation. If you do not require this wildcard access, you should disable it.
Please let us know your feedback, questions, or bug reports here. Thanks for building an app on GitHub!
All reactions